DNS, SSL & headers checker
DNS records, the TLS certificate and the security headers a domain sends — one lookup, resolved from our server.
Check a domain
What one lookup tells you about a domain
Three layers matter when you are checking a partner site, a landing page host, or your own setup. DNS records show where the domain points — the A and AAAA addresses, the mail servers (MX), the authoritative nameservers, the TXT records that carry SPF, DKIM and domain-verification tokens, and any CAA record restricting which certificate authorities may issue for it. The TLS certificate shows who issued it, when it expires, and which hostnames it covers in its SAN list — a mismatch or an imminent expiry is a real availability risk. The security headers show whether the site sends HSTS, a Content-Security-Policy, X-Frame-Options and the rest.
Reading the results
A certificate with under 15 days left is flagged amber and one that has expired is flagged red — sites do forget to renew. Missing security headers are common and not necessarily a problem for a marketing site, but a total absence of HSTS and CSP on a page that takes any user input is worth noting. The Server and X-Powered-By headers hint at the stack. DNS answers come from our server's resolvers, so a result can differ from what your users see if the domain uses geo-DNS or split-horizon; the check is a snapshot, not a monitor.